CMMC Level 1 · Reference
The CMMC Level 1 Checklist
All 15 requirements and 59 assessment objectives to work through, grouped by domain. Print this page, or follow any item through to its official text and source.
How to Use This
First find where Federal Contract Information lives in your systems. Those systems are your scope. Then work each requirement below and record a determination for it. Scope is a boundary decision you make, and each determination is yours to make and record.
Each assessment objective is determined MET, NOT MET, or N/A, and each requirement rolls up to MET or NOT MET. There is no numeric score at Level 1, and no plan of action and milestones. Every requirement must be MET, or N/A where it does not apply, before you affirm.
Access Control
AC · 19 objectives- METNOT METN/A
- AC.L1-b.1.i(a)authorized users are identified
- AC.L1-b.1.i(b)processes acting on behalf of authorized users are identified
- AC.L1-b.1.i(c)devices (and other systems) authorized to connect to the system are identified
- AC.L1-b.1.i(d)system access is limited to authorized users
- AC.L1-b.1.i(e)system access is limited to processes acting on behalf of authorized users
- AC.L1-b.1.i(f)system access is limited to authorized devices (including other systems)
- AC.L1-b.1.iii(a)connections to external systems are identified
- AC.L1-b.1.iii(b)the use of external systems is identified
- AC.L1-b.1.iii(c)connections to external systems are verified
- AC.L1-b.1.iii(d)the use of external systems is verified
- AC.L1-b.1.iii(e)connections to external systems are controlled/limited
- AC.L1-b.1.iii(f)the use of external systems is controlled/limited
- AC.L1-b.1.iv(a)individuals authorized to post or process information on publicly accessible systems are identified
- AC.L1-b.1.iv(b)procedures to ensure FCI is not posted or processed on publicly accessible systems are identified
- AC.L1-b.1.iv(c)a review process is in place prior to posting of any content to publicly accessible systems
- AC.L1-b.1.iv(d)content on publicly accessible systems is reviewed to ensure that it does not include FCI
- AC.L1-b.1.iv(e)mechanisms are in place to remove and address improper posting of FCI
Identification and Authentication
IA · 6 objectives- IA.L1-b.1.vi(a)the identity of each user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(b)the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(c)the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access
Media Protection
MP · 2 objectivesPhysical Protection
PE · 10 objectives- PE.L1-b.1.viii(a)authorized individuals allowed physical access are identified
- PE.L1-b.1.viii(b)physical access to organizational systems is limited to authorized individuals
- PE.L1-b.1.viii(c)physical access to equipment is limited to authorized individuals
- PE.L1-b.1.viii(d)physical access to operating environments is limited to authorized individuals
System and Communications Protection
SC · 10 objectives- SC.L1-b.1.x(a)the external system boundary is defined
- SC.L1-b.1.x(b)key internal system boundaries are defined
- SC.L1-b.1.x(c)communications are monitored at the external system boundary
- SC.L1-b.1.x(d)communications are monitored at key internal boundaries
- SC.L1-b.1.x(e)communications are controlled at the external system boundary
- SC.L1-b.1.x(f)communications are controlled at key internal boundaries
- SC.L1-b.1.x(g)communications are protected at the external system boundary
- SC.L1-b.1.x(h)communications are protected at key internal boundaries
System and Information Integrity
SI · 12 objectives- SI.L1-b.1.xii(a)the time within which to identify system flaws is specified
- SI.L1-b.1.xii(b)system flaws are identified within the specified time frame
- SI.L1-b.1.xii(c)the time within which to report system flaws is specified
- SI.L1-b.1.xii(d)system flaws are reported within the specified time frame
- SI.L1-b.1.xii(e)the time within which to correct system flaws is specified
- SI.L1-b.1.xii(f)system flaws are corrected within the specified time frame
- METNOT METN/A
- METNOT METN/A
- METNOT METN/A
Build the Record Behind This
AssessrLog is a working reference you do not rebuild in a spreadsheet every year. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and keep the record in one place for the six-year retention. The determination is always yours to make.
